CRISC · Question #17
An organization has decided to use an external auditor to review the control environment of an outsourced service provider. The BEST control criteria to evaluate the provider would be based on:
The correct answer is D. The organization's specific control requirements. When auditing an outsourced service provider's control environment, the best criteria are the specific control requirements of the organization utilizing the service.
Question
An organization has decided to use an external auditor to review the control environment of an outsourced service provider. The BEST control criteria to evaluate the provider would be based on:
Options
- Aa recognized industry control framework
- Bguidance provided by the external auditor
- Cthe service provider's existing controls
- DThe organization's specific control requirements
How the community answered
(27 responses)- A19% (5)
- B7% (2)
- C4% (1)
- D70% (19)
Why each option
When auditing an outsourced service provider's control environment, the best criteria are the specific control requirements of the organization utilizing the service.
While a recognized industry control framework provides a good baseline, it may not fully encompass the specific risks, regulatory requirements, or business objectives unique to the client organization.
Guidance provided by the external auditor might reflect best practices but should not be the sole basis for control criteria; the auditor's role is to assess against established criteria, not to unilaterally define them for the client.
The service provider's existing controls define their current state but may not align with the client organization's specific security posture, risk appetite, or compliance mandates, thus not being the best criteria for evaluation.
The organization's specific control requirements are the BEST criteria because the primary purpose of auditing an outsourced service provider is to ensure that the provider's controls adequately protect the client organization's assets and meet its risk tolerance and compliance obligations. While industry frameworks can inform these requirements, the client's unique business context and regulatory needs dictate what truly constitutes effective control.
Concept tested: Third-Party Risk Assessment Criteria
Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.